As part of incident response, a technician is taking an image of a compromised system and copying the image to a remote image server (192.168.45.82) . The system drive is very large but does not contain the sensitive data. The technician has limited time to complete this task. Which of the following is the BEST command for the technician to run?
A) tar cvf - / | ssh 192.168.45.82 "cat - > /images/image.tar"
B) dd if=/dev/mem | scp - 192.168.45.82:/images/image.dd
C) memdump /dev/sda1 | nc 192.168.45.82 3000
D) dd if=/dev/sda | nc 192.168.45.82 3000
Correct Answer:
Verified
Q278: An information security officer is responsible for
Q279: The Chief Information Officer (CISO) is concerned
Q280: A forensic analyst suspects that a buffer
Q281: After several industry competitors suffered data loss
Q282: A security manager recently categorized an information
Q284: Within the past six months, a company
Q285: A project manager is working with system
Q286: During the deployment of a new system,
Q287: A security administrator is troubleshooting RADIUS authentication
Q288: A company has decided to replace all
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents